Advanced Security Options for ITSAR Compliance

The Indian Telecom Security Assurance Requirements (ITSAR) security features strengthen Access Points (AP) and SmartZone (SZ) security posture by limiting AP processing of non‑essential Internet Control Message Protocol (ICMP) messages and enabling integrity and cryptographic self‑tests during boot, which improves resilience and reduces information exposure.

Feature Overview

Security features for ITSAR combine two complementary capabilities that reinforce AP and SmartZone compliance with ITSAR.

  • Restrict ICMP Processing - Restricts AP handling of non‑essential ICMPv4 message types. After enabling at the Zone level, the APs suppress ICMPv4 Timestamp Request/Reply messages and other legacy types that expose system time or attack‑surface information. SmartZone applies configuration through the management plane, APIs, and Cluster Configuration Manager (CCM) updates, and APs enforce filtering rules in the kernel networking layer after receiving updated Zone configuration.
  • Self‑Test and Reporting - Enables APs to perform security self‑tests during system boot. These tests include firmware integrity validation and cryptographic Known‑Answer Tests (KATs). When enabled at the Zone level, the AP executes self‑tests at power‑up and reports results to SmartZone, triggering an informational event that indicates success or failure of integrity and cryptographic checks. The system aligns with ITSAR and common criteria expectations by ensuring APs detect software or cryptographic module failures at an early stage. The feature interoperates with the AP boot process, the OpenSSL self‑test framework, and SmartZone event‑logging workflow.

Together, these security features reduce the attack surface, prevent exposure of sensitive system information, and add early‑boot validation of operating integrity, all of which are key security expectations in ITSAR‑aligned deployments. You can configure the features at the Zone level, with no AP Group or device‑level overrides. When enabled, APs apply enforced behavior after receiving CCM updates with advanced security settings. When disabled, APs revert to default behavior, processing all Internet Control Message Protocol (ICMP) message types according to standard networking rules and suppressing boot‑time security testing except in FIPS‑related modes. Enabling both features strengthens compliance and security assurance.

Requirements

The following requirements apply to the advanced security features:

  • APs must be running SmartZone release 7.2.0 or later firmware to support the advanced security features.

Considerations

Consider the following when configuring and using this feature:

  • ICMP suppression may affect tools that rely on Timestamp Requests for diagnostics or latency measurement.
  • Boot‑time integrity testing may slightly increase the AP startup time.

Limitations

Note the following limitations regarding this feature:

  • No AP Group or device‑level overrides permitted.
  • No periodic scheduling for self‑tests; implemented only during boot.

Best Practices

The following are best practices regarding implementation and usage of the ITSAR security features:

  • To apply advanced security options for ITSAR Compliance effectively, enable both features in a high‑security or ITSAR‑compliant environment.
  • Monitor informational event 99012 to be informed of integrity test results and boot‑time security anomalies.
  • Ensure all APs in a Zone operate on the minimum compatible firmware to prevent gating issues.

Prerequisites

This feature is supported only when all APs in the Zone run on SmartZone release 7.2.0 or later.